On 2 April 2026, Microsoft officially launched Agent Government Toolkit (AGT), an open source operating governance framework specifically designed for autonomous AI intelligence.
MIT licence to support Python/TypeScript/Rust/Go/.NET multilingual, covering all 10 OWASP Agency Top 10 risks, with a delay of less than 0.1 ms in strategy implementation.
This paper will provide a systematic answer to what the toolkit is, why it is needed, how it is used, and what it can help us achieve. 1.1 The basic definition of Agent Government Toolkit is the AI Agent operating safe governance framework.
Its core concept is to apply decades of experience in nuclear design within the operating system to the safe governance of AI smarts.
In the words of Microsoft’s official blog, “When you look at the actual behaviour of AI’s intelligent bodies in the production environment, you find a familiar model: multiple untrustworthy processes that share resources, make decisions, interact with the outside world, and their behaviour is virtually not regulated by any intermediary.
The operational system had solved the problem decades earlier — through kernels, hierarchies and processes.
The service grid solves similar problems for micro-services with mTLS and identification.
SRE addressed the reliability of the distributed system with SLO and the breaker.
Our question is: What happens when these mature models are applied to AI intelligence? " 1.2 Architecture Panorama AGT has gone through version V4.0.0 and integrated the early 45 independent packages into 5 top-level distribution packages: Distribution packages containing agent-governance-toolkit-core policy engine (Agent OS Kernel)+ Identity management (AgentMesh Platform) 1.3 The policy engine of AGT, the five core components, Agent OS (tactical engine) is the core of the system, known as the "ner core" of the AI smart body.
It operates in a state-of-the-art manner, making the horizontal extension and containerization deployment natural.
The strategic engine works in the form of an intermediate layer (rather than an OS inner kernel), sharing the same process boundary with the intelligent.
Production recommendations: Run every smart body in a stand-alone container to achieve OS class isolation.
Supported strategy language: YAML rules, OPA Rego, Cedar Policy Language.
Agent Mesh (identity and trust level) Password Identity: Generate a decentrized identifier (IDs) using Ed25519 to create an unfalsible encrypted I.I.A.T.T.T.P. for each smart body: Secure smart body rating for smart body communication protocol Dynamic trust: 0-1000 to five levels of behaviour.
Trust is dynamic - a smart body that was trusted last week but that was silent since then will gradually lose trust, which is distinct from the traditional model of binary trust/no trust. • Emergency termination of out-of-control intelligence and support for multiple causes of termination (RATE LIMIT, RING BREACH, BEHAVIORAL DRIFT, MANUAL) Agent SRE (Reliability Project) Compliance classification and regulatory framework mapping standard: OWASP Instrument Top 10, NIST AI RMF 1.0, EU AI Act, SOC 2 Type II, CSA ATF, MGF adt verify CLI Singapore generation of machine-readable evidence files that directly access the CI/CD current water line 1.4 MCP safety gateway for the MCP (Model Context Protocol) ecology, AGT: dedicated MCP Security Gateway: tool poisoning detection, drift monitoring, domain emulation (typosquatting), hidden command injection detection in MCP agreements, tool description and counterproductive content scanning.
And why it is needed in the context of 2.1: The governance gap The building of AI's intelligence has become as simple as ever - Lang Chain, Crewai, AutoGen, Microsoft Agent Framework has made it possible to do "Ai Agent" for 30 minutes.
But the problem is that there is a huge gap between the deployment of an intelligent body to a productive environment and the real governance of its behaviour.
The first Agenic AI Top 10, published by OWASP in December 2025, lists 10 types of risks specific to autonomous intelligence bodies: target hijacking, tool misuse, identity abuse, memory poisoning, cascade failure, out-of-control intelligence.
At the same time, EU AI Act ' s high-risk AI obligations came into effect in August 2026 and the Colorado AI Act came into effect in June
2026.
Regulatory pressure is forcing companies to prove "what AI has done, why, whether or not it is in compliance." 2.2 The limitations of the traditional scheme The traditional prompt-level security ( "a clause in the intuitive word to do no harm") is essentially a request rather than a compulsory one.
The conduct resulting from the LLM reasoning cannot be fully restrained by static rules — once a smart body has acquired the right of a tool to call, a small patch at the level of a hint simply cannot control what it actually does. 2.3 AGT ' s design philosophy sets out three core design principles:
1.
No state is the basis for everything by making kernel non-state, horizontal extension, containerization deployment and auditing natural and simple.
2.
Trust is dynamic, not static, and the binary trust model does not reflect reality.
An intelligent body that was trusted last week but silent thereafter will gradually lose its trust — trust requires continuous proof, not a single award.
3.
Putting AGT on a safe inside the execution path to intercept action in the execution path, rather than as an optional packaging.
The built-in security is the default security, which is often not used.
III.
How to use 3.1 Quick installation 3.2 Quick Introduction: Five minutes to add governance to Langchain ' s smart body First step: Generate a strategy template, which will produce the Manifest.yaml and policy.rego files under policies/catalogue.
Step 2: Add to the LangChain smart body each supported framework has a similar adapter: CrewCrewAdK/SoftAgentFramework/OpenAIAgentsSDK/LlamaIndex /Haystack /PydanticAI is supported.
Step three: Decorator wrapping tools (in the simplest way) Step four: Check strategy decision: Step five: Use a flash switch Step six: Create an encrypted identity 3.3 Write a policy paper 3.4 Multilingual SDK, not just Python.
AGT provides a complete cross-language SDK, all SDK shares the same strategic assessment engine and audit schema: IV, IV, and what can be achieved by the SWI02 tool: AFASP Authority Top 10 fully covered AGT is the first open-source toolkit that claims to cover all 10 of the AWASP Agency AI Top 10 risks, achieved by means of certainty (deterministic): Risk ID risk name AGT cover ASI01 target is operated with the intent to validate an ASI05 tool to intercept an ASIT + Ring + resource segregation ASI06 QA QA QA QA QA & QA QA QA QA + ETA & E2519 DID AI Top 10 + JIT authority + delegate AST + IST & SBOM signature check to implement a sandbox + Ring + resource segregation + AGO & AXA QA QA QA QA QA & QA & QA & QA QA QA QA + & 4.3 Governance scales: Accurate control of autonomous borders Microsoft suggests a metaphor for "Governance Dial": each autonomous intelligence deployment is in a spectrum from "full supervision" to "full autonomy".
It's not just a model